Purpose-Based Access Control Token Generation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Storage computing systems face challenges in implementing and managing diverse access controls for different types of data and purposes, as well as ensuring compliance with consent-based regulations, due to the variability in data types and access requirements.
Innovation Solution
A method and system that utilize purpose-based and consent-based access-control policies to modify data access by generating authorization tokens and consent tags, which anonymize, truncate, or obfuscate data, ensuring compliance with applicable policies, and managing access controls through a computing environment involving client, storage, and access-control computing systems.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If diverse access controls are implemented for different data types and purposes, then data protection and compliance are improved, but system complexity increases
Solution Approach 1:
The patent introduces an access control system as an intermediary layer between data storage and data access requests. This mediator evaluates access control policies, purposes, and consents before allowing data access, thereby simplifying the overall system architecture while maintaining strong data protection capabilities.
Solution Approach 2:
The access control system segments data access into distinct controlled dimensions: data type-specific controls, purpose-based controls, and consent-based controls. By dividing the access control function into separate evaluatable components, the system manages complexity through structured decomposition rather than monolithic control.
2Object-affected harmful factors
If purpose-based access controls are implemented, then data security is improved, but access management difficulty increases
Solution Approach 1:
The system performs preliminary evaluation of access control policies, purposes, and consents before data access is granted. By pre-establishing and pre-evaluating access control dimensions, the system simplifies the data access operation itself while maintaining strong security controls.
3Reliability
If consent-based access controls are implemented, then user privacy is improved, but system complexity increases
Solution Approach 1:
The access control system serves as an intermediary that handles consent management centrally. It evaluates consent status, purposes, and data types in a unified manner, simplifying consent management complexity while maintaining strong user privacy protection across multiple data access scenarios.
4Reliability
If multiple access control policies are managed, then compliance is improved, but operational complexity increases
Solution Approach 1:
The access control system is designed with multi-functionality to handle multiple compliance requirements and policy types through a unified framework. It can evaluate different policy dimensions (data type, purpose, consent) using the same underlying mechanisms, simplifying policy management while maintaining comprehensive compliance coverage.
Data Source
AI summary
Aspects of the present invention provide methods, apparatuses, systems, computing devices, computing entities, and/or the like for implementing and managing access to particular data based on access controls for implementing purpose restrictions and/or consent restrictions. In various aspects, a method is provided that comprises: receiving a request transmitted by an application executing on a client computing system and requesting access to a dataset, wherein each data record of the dataset comprises data elements; identifying, based on the application, a purpose for the application requesting access to the dataset; referencing, based on the purpose, an applicable purpose-based access-control policy to identify an authorization token; and providing the authorization token, wherein the storage computing system provides the client computing system with a view of the dataset based on the token with the view having a data element returning modified data in a manner compliant with the applicable purpose-based access-control policy.


